file: Heap-based buffer overflow A heap-based buffer overflow in file might allow remote attackers to execute arbitrary code. file 2020-03-15 2020-03-15 698610 local, remote 5.37-r1 5.37-r1

file is a utility that guesses a file format by scanning binary data for patterns.

It was discovered that file incorrectly handled certain malformed files.

A remote attacker could entice a user to process a specially crafted file via libmagic or file, possibly resulting in execution of arbitrary code with the privileges of the process or a Denial of Service condition.

There is no known workaround at this time.

All file users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=sys-apps/file-5.37-r1"
CVE-2019-18218 whissi whissi